#CSRF
All CosmicBytez Labs articles tagged #CSRF, across news, security advisories, how-to guides, and projects.
- News
Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
CVE-2026-62062 (CVSS 8.8) lets one clicked link create a rogue WordPress admin via Elementor's broken CSRF check on 2M+ sites.
- News
Elementor WordPress Flaw Lets Attackers Create Admin Accounts
A CSRF flaw in Elementor 4.3.0 and 4.3.1 (CVE-2026-62062) bypassed REST nonce checks, letting attackers create rogue WordPress admin accounts.
- News
Click2Shell PoC Exploit Code Now Public for Patched WordPress CSRF Flaw
Researcher Paulos Yibelo published full technical details and working exploit code for the WordPress Click2Shell CSRF-to-RCE chain.
- News
New WordPress 'Click2Shell' Flaw Forces Theme Installs, Can Chain to Code Execution
A URL-parsing mismatch lets one link silently install a WordPress theme for a logged-in admin, chainable to critical remote code execution.
- Security
WebTotem Backups Plugin Lets Any Subscriber Delete WordPress Files
CVE-2026-77006 lets low-privilege WordPress users delete arbitrary server files after the plugin discards its own CSRF check result.
- Security
CSRF-to-RCE File Upload Flaw in Gpx2Graphics Plugin
CVE-2026-81090 lets attackers trick a logged-in WordPress admin into uploading a PHP webshell through the Gpx2Graphics plugin.
- Security
CVE-2008-4128: Cisco IOS Cross-Site Request Forgery Vulnerability
Cisco IOS 12.4 contains multiple CSRF vulnerabilities that allow remote attackers to execute arbitrary commands. The flaw has been added to the CISA Known...
- Security
CVE-2026-9733: Mojolicious OAuth2 Weak PRNG Enables CSRF Session Hijacking
A critical flaw in the Mojolicious::Plugin::Web::Auth::OAuth2 Perl module uses a predictable SHA-1 state derived from epoch time and rand(), allowing...
- Security
CVE-2026-2611: MLflow 3.9.0 Improper Origin Validation
A critical CVSS 9.6 vulnerability in MLflow 3.9.0 allows a remote attacker to exploit improper origin validation in the MLflow Assistant's /ajax-api...
- Security
CVE-2026-3589: WooCommerce CSRF Flaw Allows Unauthenticated
A cross-site request forgery vulnerability in WooCommerce versions 5.4.0 through 10.5.2 allows attackers to abuse the Store API's batch endpoint to...